Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the use of package installation commands (pip, npm, npx) where the package name resembles popular AI/ML libraries (tensorflow, torch, openai, langchain) but is not an exact match for known legitimate versions. This is a common indicator of a typosquatting supply chain attack, where attackers attempt to trick users into installing malicious packages with similar names to trusted software.
Detects Python or Pip processes that download an image file from the network and subsequently write a native extension module (.pyd or .so) to the disk within a 10-minute window. This behavior is consistent with the extraction of a hidden malicious payload embedded within an image file using steganography.
Detects a single source IP address attempting to connect to multiple hosts over TCP port 3389 (RDP) within a short timeframe (10 attempts in 60 seconds). This behavior is indicative of a host scanning the network for accessible RDP services, a common precursor to lateral movement or brute force attacks.
Detects high-frequency TCP connection attempts to WinRM (port 5985) originating from a single source host within the internal network. This pattern of behavior is often indicative of an adversary attempting to scan for or move laterally to multiple systems using WinRM.
Detects multiple attempts to connect to administrative shares (ADMIN$, C$, IPC$) from a single source within a 60-second window. This pattern is indicative of automated lateral movement or enumeration attempts using the SMB protocol.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by using reflection to modify internal AMSI-related structures and memory flags (e.g., AmsiUtils, amsiInitFailed). This technique involves manipulating system objects to neutralize AMSI's ability to inspect malicious script content.
Detects potential Golden Ticket forgery or malicious Kerberos activity by monitoring Windows Security Event IDs 4768 (TGT) and 4769 (TGS). The rule identifies suspicious characteristics including the use of weak encryption (RC4) where AES is preferred, specific ticket option flags commonly associated with Mimikatz, and unusually long ticket lifetimes that deviate from standard domain policies.
Detects the deletion of Volume Shadow Copies and disabling of Windows boot recovery options using native administrative utilities such as vssadmin, wmic, powershell, wbadmin, and bcdedit. This behavior is frequently associated with pre-encryption activities in ransomware attacks to prevent system restoration.
Detects potential reflective DLL injection or process hollowing attempts by monitoring for high-privilege cross-process access (ProcessAccess EventID 10) or remote thread creation (CreateRemoteThread EventID 8). These methods are frequently used by attackers to execute malicious code within the memory space of a legitimate target process, thereby evading traditional signature-based detection.
Detects the suspicious execution of common Windows system binaries (LOLBAS) often used for proxying malicious code execution or deobfuscating payloads. This includes regsvr32.exe for remote scriptlet execution, mshta.exe for remote HTA execution, rundll32.exe for JavaScript or DLL function execution, and certutil.exe for decoding or retrieving remote files.
Detects potential Pass-the-Hash (PtH) activity where a single user account performs NTLM Type 3 (network) authentications to three or more unique destination hosts within a 10-minute window, excluding service account activity (trailing $). This pattern is consistent with an adversary moving laterally across a network using harvested NTLM hashes.
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in-memory by monitoring command lines of common script-hosting processes (e.g., PowerShell, WScript, Rundll32) for strings indicative of AmsiScanBuffer patching, reflection, or manual configuration of AMSI initialization states.
Detects the use of the built-in Windows utility rundll32.exe to execute comsvcs.dll with the MiniDump command to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. This is a common technique used by attackers to harvest credentials from memory.
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete shadow copies, backup catalogs, or modify boot configuration data to disable recovery. This behavior is commonly associated with ransomware and data destruction attacks intended to prevent system restoration.
This rule detects unauthorized directory replication requests (DRSUAPI) using Active Directory Event ID 4662. It specifically monitors for access requests to sensitive directory replication object GUIDs (Get-Changes / Get-Changes-All) where the requesting user account is not a domain controller computer account. This behavior is a common indicator of DCSync credential dumping attacks performed by tools like Mimikatz or Impacket.
Detects the 'ClickFix' technique where a user copies a malicious payload and pastes it into the Windows Run dialog (Win+R). The rule monitors for the creation of registry values under the RunMRU key followed closely by the execution of powershell.exe or cmd.exe initiated directly by explorer.exe, indicating an bypass of standard browser execution chains.
This rule detects persistence establishment via Scheduled Task creation shortly (within 15 minutes) after a suspicious PowerShell process execution. The PowerShell execution matches the 'ClickFix' pattern, characterized by hidden/bypass window styles and the invocation of remote download or execution cmdlets (e.g., IEX, IRM).
This rule detects potentially malicious in-memory module loading, such as Beacon Object File (BOF) execution, on hosts already identified as exhibiting suspicious behavior related to MLTBackdoor or sideloading activity. It monitors for memory allocation or protection changes (AllocateVirtualMemory, VirtualProtect, CreateRemoteThread) that result in executable memory (RWX or execute-only) without a corresponding file on disk, which is a common indicator of fileless code injection.
This rule detects potential Browser-in-the-Browser (BitB) phishing attacks by identifying suspicious browser pop-up behavior (using window.open flags, hidden address/toolbars) on non-identity-provider domains, followed shortly by credential submission patterns on the same device. This pattern mimics legitimate OAuth or SSO windows to harvest user credentials.
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
Page 41 of 1870


